GDPR Data Privacy Professional
Comprehensive training that covers all aspects of GDPR and teaches how to apply them in practice. You’ll build a firm foundation in data privacy, combining theoretical knowledge with up-to-date practical skills.
- September 26 → October 21
- €935 + VAT
- GDPR theory & basic practical skills
- Online classes, Q&A-sessions with trainers, final project
- Self-assessement tests and practical tasks
- Electronic certificate in Accredible
This Course Stands at the Source of Data Protection in Europe
We built GDPR Data Privacy Professional training in 2018 — in the begginning of the GDPR era — as a solution for increasing demand for qualified data privacy specialists. The creator of this program — Siarhei Varankevich — had experience of working with the draft of the GDPR and got knowledge of each and every small detail and pifall of the regulation. For 8 years already we’ve been helping diverse specialists to undersatnd the law and implement iteffectively among their companies.
Who is this course suitable for?
Professionals who are starting their journey in data privacy.
We’ll cover the fundamentals of personal data protection: its history, the logic behind the laws, and the first steps to building a system.
DPOs ‘by accident’ who are already working with personal data protection but want to systematize their knowledge.
We’ll explain the key provisions of GDPR and provide additional materials to help you understand the nuances of the articles.
Current personal data protection specialists who have not previously worked with European law.
We’ll examine how European data protection law was formed and in which direction it is developing now.
Course Format
- €935 + VAT
- Mix format — pre-recorded lectures + live-online weekly sessions with trainers
- 4 weeks
- Tests, practical tasks with feedback from the trainer
- Final team project: creating a Record of Processing Activities (RoPA)
- Hands-on experience with Miro and Notion tools
- Electronic certificate via Accredible upon successful test completion (over 80% correct answers)
Program
Privacy
- Concept of privacy, information privacy and personal data protection, types of privacy.
- History of information privacy.
- Daniel Solow’s classification of privacy violations.
- The role of information privacy in society.
- Review of the evolution of the legal regulation of personal data protection.
Law
- Overview of existing laws, standards and regulations on data protection.
- Cases, court decisions, clarifications in the field of information privacy.
- Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data No. 108.
- Directive 95/46.
GDPR
- Overview of present regulatory framework of data protection in EU (GDPR+).
- History of EU General Data Protection Regulation (GDPR).
- Territorial and material scope of GDPR.
- Structure of GDPR text (recitals, business related articles etc).
- Overview GDPR related acts.
- National data privacy legislation.
- Legal precedents.
- Guidelines and opinions of Article 29 Working Group (Art29WP) / European Data Protection Board (EDPB).
- Guidelines of national supervisory authorities (SAs).
- Overview of risks, fines, responsibilities related to personal data processing.
- Mapping of the different data protection laws to the rules applicable in EU.
Concept of personal data
Data processing. Data controllers and processors
- Personal data processing and its types.
- Profiling.
- Personal data pseudonymisation.
- Personal data anonymisation.
- Processing of special categories of personal data.
- Processing of minors’ data.
- Data controller, co-controllers or individual controllers.
- Data processor.
- Distribution of responsibilities between controller and processor.
Principles
- Data minimisation.
- Storage limitation.
- Accuracy.
- Integrity and confidentiality.
- Accountability.
- Transparency of processing.
- Purpose limitation.
Privacy by Design
- The 7 foundational principles of privacy by design by Ann Cavoukian.
- Privacy by Default.
- Privacy embedded into design.
- Full functionality – positive-sum.
- End-to-End Security – Lifecycle Protection.
Lawful basis for processing
- Consent.
- Conditions for consent.
- Getting consent in UX.
- Contract.
- Legal obligation.
- Vital interest.
- Public interest.
- Legitimate interest.
- Balancing test of Legitimate Interest Assessment (LIA).
Data subject rights
- Modalities for exercise of the rights of the data subject.
- Right to information about processing.
- Right to access personal data.
- Right to rectification.
- Right to restriction of processing.
- Right to be forgotten.
- Right to data portability.
- Right to object.
- Right to not be subject of automated decision-making.
- Data subject’ rights restriction.
- Case “Nightmare letter from data subject”.
DPIA and privacy risk management
- Check-box approach vs risk based approach.
- Concept of risk.
- Risk likelihood and severity.
- GDPR terminology related to risks (high risk, likely etc).
- Data Protection Impact Assessment (DPIA) requirement under GDPR.
- When DPIA is mandatory.
- BIA (Business Impact Assessment) or SIA (Security Impact Assessment) as triggers for DPIA.
- General approach to conduct DPIA.
- Describing processing operations, personal data and supporting assets.
- Legal and risk-treatment controls.
- Risk sources, feared events, threats and risks.
- Tools for Data Protection Impact Assessment.
Information security
- GDPR requirements to information security.
- Data breach notification of supervisory authorities and data subjects.
- Technical and organisational measures of managing information security risks.
Trans-border transfers of personal data
- Overview of GDPR rules on cross-border data flow.
- Documenting international transfers of personal data.
- Data Processing Agreement.
- Binding Corporate Rules.
- Standard Contractual Clauses.
- Codes of conduct and certifications.
- Derogations relating to cross-border data transfers for specific situations.
Data protection officer (DPO) and EU representative
- Representative in EU.
- Data Protection Officer / DPO.
Schedule
- September 26 → October 21
Your CV after training
- Understand and easily navigate GDPR articles, recitals, guidelines, and opinions.
- Create and maintain a high-quality personal data protection system across all business areas.
- Advise employees from various departments on personal data protection matters.
- Develop and maintain up-to-date personal data protection documents (Privacy Policy, Cookie Policy, etc.).
- Document cross-border data transfers.
- Assess the existing personal data protection system, identify gaps, and address them.
- Apply the Regulation's requirements in practice.
- Develop a Record of Processing Activities.
- Identify, prevent, and mitigate privacy-related risks.
- Conduct audits to ensure compliance and resolve potential issues.
GDPR
Data Privacy Audit
Personal Data Protection System
Personal Data Protection System
DPIA
RoPA
Privacy Policy
Personal Data Protection Documents
Ccross-border Data Transfer
Data Mapping
Why Is This Course Your Best Choice?
Structured and up-to-date program
Our GDPR DPP course program has been validated by hundreds of graduates and is continually updated to reflect the latest regulation changes and trends.
Practical assignments and final team project
You’ll apply your knowledge through practical exercises after each theoretical module, take tests, and collaborate on a team final project.
Certified trainer
Learn from Siarhei Varankevich, CIPP/E, CIPM, CIPT, MBA, FIP—founder of Data Privacy Office Europe, chief editor of GDPR-Text.com, and creator of Applicability App.
Learning with like-minded people and networking
Studying alongside others who share your interests boosts motivation and enhances results. This environment fosters idea discussions, news sharing, and open Q&A sessions.
Systematized learning materials
Access author-created Miro boards and over 100 useful resources: guidelines, diagrams, checklists, and supervisory documents.
50 % Off for Full-Time Students
We want to support students in their professional growth. That’s why we offer a 50% discount to all full-time students on our fundamentalGDPR Data Privacy Professional training.
Please note: A valid student ID is required when enrolling.
Feedback
Among the many merits of the program, I would like to highlight the following: extensive experience in the field of privacy protection and high professionalism of the trainer Siarhei Varankevich, teaching talent combined with maximum involvement in the educational process, organization of training in small groups, well-thought-out training format, volume and quality of the provided additional materials and constant organizational support.
Learn more…
We would especially like to note the high qualifications of Siarhei Varankevich, the trainer for this course. The instructor’s strong points include openness and the ability to connect with the audience, engage participants, and maintain interest in the subject matter. We thank you for the systematic, competent, and substantive approach to the training process, delivery of material to participants, experience, and practical recommendations.
Learn more…
During this short but extremely informative course, trainer Siarhei Varankevich managed to give our team a vision of the big picture around personal data, and from a practical standpoint, clearly explained what activities and approaches are necessary for compliance with the main GDPR requirements in our work. The course exceeded our team’s expectations by far, and planted the seeds for further deepening into the topic of a competent approach to working with personal data.
Learn more…
Here are my ratings:
1. The training organization process — 5 out of 5. Special thanks to the learning support team.
2. The training itself — 5 out of 5. Immediately after the training, I became capable of solving corporate issues (obviously not at a legal level, but still).
3. The learning support process — 5 out of 5. There was always feedback.
Learn more…
I really want to thank the organizers of the “GDPR Data Privacy Professional (GDPR DPP)” course and personally Siarhei Varankevich, who teaches such complex things as Data Privacy in a very accessible yet professional manner. The material, thanks to thorough refinement and adaptation, is truly easy to absorb. But the expectations are worth it, because after completing the course, many things become very clear, and if any questions related to Data Privacy come up at work, they no longer seem so complicated and convoluted.
Learn more…
I took the course after already studying the Regulation for quite a long time. I can say that my knowledge definitely became more detailed and deeper. Moreover, the position presented in the course aligns with the positions of EU national data protection regulators, meaning one can assume that this particular “interpretation” of the Regulation is correct and will help avoid problems in the future. Thank you!
Learn more…
The company took a responsible approach to organizing and conducting the training course. All issues were resolved in a timely manner. The course itself is built on a solid methodological foundation — GDPR provisions are supported/explained by other EU regulatory documents and legal precedents. There is an opportunity to discuss with the instructor questions that arise in practice, examine specific personal data processing situations, and evaluate them from a GDPR perspective.
Learn more…
The GDPR DPP course is the best you can find on this topic. The training itself is very dynamic, with complete immersion in GDPR matters. I can highly recommend it to fellow lawyers working with personal data — it will be extremely useful. Special thanks to Siarhei Varankevich — an excellent trainer who provides a wealth of invaluable information and teaches you how to think correctly (which is very important)!
Learn more…
I want to express infinite gratitude to Siarhei Varankevich and his highly professional team for the most interesting, deep, and rich Data Privacy Professional course. I was impressed by both the high technical preparation of the course and the mastery of the course leader! I discovered interesting tools for work, upgraded my knowledge in the field of privacy and GDPR in general, and met interesting people. I was charged with powerful energy, the drive continues to this day, my brain is buzzing.
Learn more…
Upon completion of the course, my knowledge of the Regulation deepened significantly, as various aspects were covered: case law, decisions of supervisory authorities, technical sides of compliance, real-life cases (including those taking into account post-Soviet realities). In addition, our truly remarkable trainer Siarhei Varankevich talked about the very origins of the concept of “privacy,” how it led to the emergence of GDPR, and where pan-European legislation in this area is heading.
Learn more…
I am very satisfied that I completed the GDPR course. It was incredibly useful and informative training that helped me better understand aspects of personal data protection.
The course provided me with knowledge on how to manage data and how to effectively respond to potential security breaches. I also received valuable information on how to create privacy policies for my company.
Learn more…
The DPP course helped me study the structure of GDPR and the principles of how it works, as well as understand sources of additional information for working through the most complex and controversial issues, dive deeper into each section of the regulation, fill gaps in my knowledge and structure it.
Learn more…
The GDPR Data Privacy Professional course was very impressive. Everything is clear and understandable, with a huge number of illustrative examples. The coordinators were always available despite being very busy, which is very pleasant. Huge thanks to Siarhei Varankevich and the team for this course!
Learn more…
I would like to express my gratitude to the team for the excellent GDPR Data Privacy Professional course. Special thanks to Siarhei Varankevich for the outstanding theoretical material and the opportunity to ask and discuss questions during webinars. The course is particularly valuable because the learning process includes not only theory but also teamwork on practical assignments. The entire training is organized at the highest level and excellently systematized.
Learn more…
Course Trainer
Become a Leader in GDPR Compliance
Complete the form to get:
- Directions on cost, duration, and other details.
- Opportunity to ask questions concerning AI compliance and data protection.
- Understanding if this product is right for your business or project.
Frequently Asked Questions
What if I can’t attend live sessions during the GDPR training?
No worries! Our online course format is designed for flexibility. All lectures are pre-recorded, so you can learn at your own pace and still gain a solid understanding of EU General Data Protection Regulation (GDPR).
Recordings of live Q&A sessions with our trainers are also provided.
If you fall behind, we can help you transfer to the next course cohort to ensure you stay on your structured learning path without missing any valuable content.
Is it possible to pay for the GDPR course in installments?
Absolutely! You can pay for this training through several installments.
Our managers will help you find favorable terms tailored to your needs so that you can focus fully on your learning experience and developing knowledge and skills in data protection practices.
Do you offer student discounts for the course?
Yes, we do!
We offer a 50% discount for all full-time students enrolling in the training. This is part of our mission to help students gain a thorough understanding of privacy law and start a successful career in data protection.
Simply apply through the website, and our team will guide you through the process. You’ll only need to present your student ID when signing the training agreement.
Can I take the CIPP/E certification exam right after completing the course?
While this course gives you deep GDPR knowledge and practical tools to ensure compliance with GDPR, it’s not designed as direct exam preparation.
Instead, it provides the GDPR foundation and hands-on expertise you need to work confidently in data privacy and other privacy regulations.
If you wish to pursue CIPP/E certification, our managers will be happy to advise you on the next steps.
Does the GDPR Data Privacy Professional course focus only on theory?
Not at all: this GDPR training course blends theory and practice.
You’ll apply what you learn through self-assessment tests, practical exercises, and a final team project where you create a Record of Processing Activities (RoPA).
You’ll also explore best practices for handling personal data, performing Data Protection Impact Assessments (DPIAs), and managing data breaches in compliance with European data protection standards.
What level of experience do I need to join this GDPR course?
- Professionals new to data privacy principles and data controllers roles.
- Specialists who want to align their data processing activities with GDPR requirements.
- Experienced professionals outside of the European Union who want to comply with the GDPR and protect the privacy of individuals when processing data outside the EU.
What practical outcomes can I expect after completing the GDPR DPP training?
After finishing this foundation and practitioner training course, you’ll be able to:
- Advise on rights of data subjects and handle data subject requests effectively.
- Conduct Data Protection Impact Assessments (DPIAs) and implement security measures to minimize the risk of a breach.
- Develop and maintain documentation such as Privacy Policies, Cookie Policies, and Data Processing Agreements.
- Understand cross-border data transfer requirements and manage data flows in compliance with EU law.
- Apply best practices to ensure compliance and protect personal data of individuals both within and outside of the EU.
This course equips you with real-world GDPR tools, helping you translate theory into action and build a strong compliance program for your organization.